|
223401
|
9.8 |
CRITICAL
Network
|
glpi_dashboard_project
|
glpi_dashboard
|
Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.
|
CWE-287
Improper Authentication
|
CVE-2019-12530
|
2024-11-21 13:23 |
2019-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223402
|
7.1 |
HIGH
Local
|
glyphandcog
|
xpdfreader
|
There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pd…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-12515
|
2024-11-21 13:23 |
2019-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223403
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12359
|
2024-11-21 13:22 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223404
|
8.8 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.
|
CWE-89
SQL Injection
|
CVE-2019-12358
|
2024-11-21 13:22 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223405
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12357
|
2024-11-21 13:22 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223406
|
8.8 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12356
|
2024-11-21 13:22 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223407
|
8.8 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12355
|
2024-11-21 13:22 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223408
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12354
|
2024-11-21 13:22 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223409
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12353
|
2024-11-21 13:22 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223410
|
8.8 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.
|
CWE-89
SQL Injection
|
CVE-2019-12352
|
2024-11-21 13:22 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|